Avenlor
Home / Insights / Governance
Governance

Related-Party Transactions

The transactions most likely to damage a company are rarely with strangers — they are with the people who control it. Related-party dealings are legitimate and everyday, but they are where conflicts of interest, value leakage, and regulatory findings concentrate. Governing them is about one thing: making them visible, fairly priced, and approved by people with nothing to gain.

Avenlor ConsultingGovernance & Internal Controls8 min read

A company buys its office space from a building the chairman owns. It sources a key material from a supplier run by the CEO's brother. It lends money to a shareholder, or guarantees their personal borrowing. None of these is wrong in itself — related parties are often the most convenient, trusted, or available counterparties a business has. But each one carries the same latent risk: the person on the other side of the table also sits, in some form, on your side of it.

That is what makes related-party transactions (RPTs) a governance flashpoint. They are the mechanism through which value can quietly leave a company on terms it would never accept from a stranger — and the first place a regulator, an auditor, or a minority shareholder looks when they suspect it has. In Saudi Arabia they sit high in the Capital Market Authority's expectations for listed companies, and in family enterprises they are simply a fact of daily life. Either way, the goal is not to ban them. It is to govern them.

Who counts as a related party

You cannot control what you have not defined. A related party is, broadly, anyone close enough to the company to influence — or be influenced by — a decision that should be made at arm's length:

A related-party transaction is then any dealing between the company and one of these parties: a sale, a purchase, a lease, a loan, a guarantee, a service agreement, or a transfer of assets. The value can be large or small; the relationship is what makes it a related-party transaction, not the size.

The single principle: arm's length, independently approved

Almost everything sound about governing RPTs reduces to two tests applied together. First, is the transaction on arm's-length terms — the same price and conditions the company would agree with an unrelated party? Second, was it approved by people without the conflict — decided by those who do not stand to benefit? A related-party deal that passes both is usually fine. One that fails either is where the damage is done.

The problem is almost never that a company deals with related parties. It is that it deals with them on terms, and through approvals, it would never accept from anyone else.

You cannot control what you cannot see

The first control is simply knowing who your related parties are. That means maintaining a related-party register — a living list of directors, executives, major shareholders, their family connections, and the entities they control — and a declaration process that keeps it current as people join, leave, and acquire new interests. Without it, related-party transactions are not being approved as such; they are just being processed as ordinary business, which is exactly how they slip past controls.

Disclose, then step back

When a transaction involves a related party, the conflicted individual has two obligations, in order: declare the interest, fully and early, and then step out of the decision. A director with an interest in a contract should not be in the room advocating for it, and certainly should not vote on it. Recusal is not a courtesy — it is the mechanism that lets the remaining, disinterested decision-makers approve or reject the deal on its merits. A declaration without a stepping-back is only half the control.

Route it to the right level

Related-party transactions should almost always escalate. Your delegation of authority should treat them as a category that rises regardless of value — never approved quietly at a manager's desk. Depending on materiality, the approver may be the board, the audit committee, or, for the most significant transactions, the shareholders themselves — with the interested parties excluded from the vote. The more material the transaction and the more concentrated the conflict, the higher and more independent the approval must be.

Price it, and prove the price

"Arm's length" is a claim until it is evidenced. For routine or low-value transactions, a documented comparison to market terms may be enough. For material ones — a significant asset transfer, a large lease, a major supply contract — an independent valuation or benchmark is what turns the assertion into something an auditor can test. The file should show not just that the transaction was approved, but why the price was judged fair, and against what.

The family-business dimension

In a family enterprise, related-party transactions are not an occasional event — they are woven through the business. Rent paid to a family-owned property, purchases from a relative's company, loans between the business and its shareholders, family members employed in the firm: all normal, and all related-party transactions. The risk is not that they happen, but that they happen on undocumented, undisclosed, informal terms — which is precisely what erodes trust between family branches and alarms any outside investor or lender. Bringing these dealings onto clear, disclosed, arm's-length terms is often one of the highest-value steps in professionalising a family company's governance.

A control path for related-party transactions

  • A related-party register, kept current through a declaration process
  • Every transaction screened against the register before it is processed
  • The interested party declares the conflict and steps out of the decision
  • Escalation regardless of value — to board, audit committee, or shareholders by materiality
  • Arm's-length pricing, with an independent valuation for material transactions
  • A documented rationale showing why the terms were judged fair
  • Disclosure in the financial statements as required, and to those approving

Handled well, related-party transactions are simply part of doing business with the people and entities around you. Handled badly, they are the single clearest sign — to a regulator, an auditor, or a shareholder deciding whether to trust you — that the company is run for the benefit of insiders rather than of the company itself. The controls above are what keep you firmly on the right side of that line.

Bringing related-party dealings onto clear terms?

We build related-party registers, conflict-of-interest and approval frameworks, and the disclosure discipline that withstands regulatory and audit review — for listed and family companies alike.

Discuss your mandate →

Read next

Governance for Saudi Family Businesses → The Audit Committee: The Board's Line of Sight →

This article is general guidance on governance practice and does not constitute legal, audit, or regulatory advice. Requirements depend on your circumstances and the applicable regulations at the time; obtain professional advice for your specific engagement.